Microsoft warns Windows PC users of Russian hackers on hotel WiFi | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Microsoft issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks.

“Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing,” Microsoft said in its warning released Friday.

Microsoft issued the warning after discovering CaptiveCrunch, a global campaign that the company attributed to Storm-2945, a sub-cluster of Russia’s Midnight Blizzard, Forbes reported. CaptiveCrunch targets corporate travelers with credential theft and malware delivered through compromised guest networks.

The tech company has been aware of the campaign since May, and it has impacted hospitality networks and other guest networks served by captive portals worldwide.

A July report from ReliaQuest found that hackers were targeting Microsoft 365 users through compromised WiFi gateways. The hackers would redirect guests to fake sign-in pages, but without first sending a phishing email or compromising the PC.

Microsoft Threat Intelligence thanked “Anthropic and OpenAI for their collaboration and support during this investigation.” The tech company also said that Storm-2945 used AI to support CaptiveCrunch.

“In addition to variants of malware targeting Windows systems, Microsoft Threat Intelligence is also aware of indications that the threat actor might be targeting Android devices with similar techniques as the ClickFix landings also include instructions for Android devices to download and install an APK file,” the company added.

The hackers attack hospitality networks to display fake verification checks, sign-in prompts, and software updates. The pages appear while users are connecting through a hotel or venue’s legitimate WiFi gateway, which makes it difficult for users to recognize.

Some users are directed to Microsoft’s legitimate device-code authentication process, through which the hacker initiates a sign-in attempt and persuades users to enter a code the hacker gives them. If the user approves the request, Microsoft issues valid authentication tokens to enable access to their account without needing to steal a password or directly bypass multi-factor authentication.

Microsoft also said that the attacks can deliver malware directly to users’ devices and disguise it as Windows updates.

The tech company has called the Windows remote-access trojan (RAT) CornFlake. The RAT is designed to record keystrokes, collect files, steal credentials and session tokens, and capture screenshots. CornFlake can also hijack a device’s audio and video capabilities for surveillance, and give hackers persistent access.

Microsoft advises travelers not to trust hotel, conference, airport, and other guest networks. The company recommends using mobile hotspots, cellular connections, or other private connectivity, avoiding updates through captive portals, strengthening Conditional Access and phishing-resistant authentication, and blocking device-code authentication when not required.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW